mirror of
https://github.com/community-scripts/ProxmoxVE.git
synced 2026-09-12 15:40:45 +02:00
Compare commits
10 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| df1c353cb2 | |||
| 2c6a578343 | |||
| b068e7cd8a | |||
| 02cf8a0a8f | |||
| 9580c0f5bd | |||
| 3dbfe54701 | |||
| ab5f20ec71 | |||
| 0a48435ef9 | |||
| 9e22ffe10d | |||
| 4412cc0eae |
@@ -542,12 +542,23 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
|
||||
|
||||
## 2026-09-12
|
||||
|
||||
### 🆕 New Scripts
|
||||
|
||||
- Hammer ([#17189](https://github.com/community-scripts/ProxmoxVE/pull/17189))
|
||||
- gotenberg ([#17205](https://github.com/community-scripts/ProxmoxVE/pull/17205))
|
||||
|
||||
### 🚀 Updated Scripts
|
||||
|
||||
- #### 🐞 Bug Fixes
|
||||
|
||||
- fix(dispatcharr): add comskip installation and build dependencies [@eXistC](https://github.com/eXistC) ([#16224](https://github.com/community-scripts/ProxmoxVE/pull/16224))
|
||||
- poznote: serve from src/public docroot [@MickLesk](https://github.com/MickLesk) ([#17187](https://github.com/community-scripts/ProxmoxVE/pull/17187))
|
||||
- calibre-web: use calibreweb release identifier to avoid version file collision [@MickLesk](https://github.com/MickLesk) ([#17186](https://github.com/community-scripts/ProxmoxVE/pull/17186))
|
||||
|
||||
- #### ✨ New Features
|
||||
|
||||
- feat(jitsi-meet): optional public setup (FQDN, Let's Encrypt, NAT, secure domain) [@klanghans](https://github.com/klanghans) ([#17132](https://github.com/community-scripts/ProxmoxVE/pull/17132))
|
||||
|
||||
## 2026-09-11
|
||||
|
||||
### 🆕 New Scripts
|
||||
|
||||
+12
-1
@@ -106,7 +106,18 @@ EOF
|
||||
msg_ok "Migrated Nginx Configuration"
|
||||
fi
|
||||
|
||||
ensure_dependencies vlc-bin vlc-plugin-base
|
||||
ensure_dependencies vlc-bin vlc-plugin-base build-essential autoconf libtool libargtable2-dev libavformat-dev libsdl2-dev libswscale-dev
|
||||
|
||||
if ! command -v comskip &> /dev/null; then
|
||||
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "Comskip" "erikkaashoek/Comskip" "tarball"
|
||||
msg_info "Compiling Comskip"
|
||||
cd /opt/Comskip
|
||||
$STD ./autogen.sh
|
||||
$STD ./configure
|
||||
$STD make
|
||||
$STD make install
|
||||
msg_ok "Compiled and Installed Comskip"
|
||||
fi
|
||||
|
||||
if check_for_gh_release "Dispatcharr" "Dispatcharr/Dispatcharr"; then
|
||||
msg_info "Stopping Services"
|
||||
|
||||
@@ -0,0 +1,75 @@
|
||||
#!/usr/bin/env bash
|
||||
_CS_DEFAULT_URL="https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main"
|
||||
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
|
||||
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: CrazyWolf13
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://github.com/gotenberg/gotenberg
|
||||
|
||||
APP="Gotenberg"
|
||||
var_tags="${var_tags:-document;pdf}"
|
||||
var_cpu="${var_cpu:-2}"
|
||||
var_ram="${var_ram:-4096}"
|
||||
var_disk="${var_disk:-15}"
|
||||
var_os="${var_os:-debian}"
|
||||
var_version="${var_version:-13}"
|
||||
#var_arm64="${var_arm64:-no}" # unset = ask the user; set yes/no only when verified
|
||||
var_unprivileged="${var_unprivileged:-1}"
|
||||
|
||||
header_info "$APP"
|
||||
variables
|
||||
color
|
||||
catch_errors
|
||||
|
||||
function update_script() {
|
||||
header_info
|
||||
check_container_storage
|
||||
check_container_resources
|
||||
|
||||
if [[ ! -f /etc/systemd/system/gotenberg.service ]]; then
|
||||
msg_error "No ${APP} Installation Found!"
|
||||
exit
|
||||
fi
|
||||
|
||||
if check_for_gh_release "gotenberg" "gotenberg/gotenberg"; then
|
||||
msg_info "Stopping Service"
|
||||
systemctl stop gotenberg
|
||||
msg_ok "Stopped Service"
|
||||
|
||||
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "gotenberg" "gotenberg/gotenberg" "tarball" "latest" "/opt/gotenberg"
|
||||
|
||||
GO_VERSION="$(awk '$1=="go"{print $2}' /opt/gotenberg/go.mod | cut -d. -f1,2)" setup_go
|
||||
|
||||
msg_info "Building gotenberg (Patience)"
|
||||
cd /opt/gotenberg
|
||||
export CGO_ENABLED=0
|
||||
$STD go mod download
|
||||
$STD go build -o /usr/local/bin/gotenberg \
|
||||
-ldflags "-s -w -X 'github.com/gotenberg/gotenberg/v8/cmd.Version=$(cat ~/.gotenberg)'" \
|
||||
cmd/gotenberg/main.go
|
||||
msg_ok "Built gotenberg"
|
||||
|
||||
msg_info "Updating unoconverter"
|
||||
UNOCONVERTER_VERSION=$(get_latest_github_release "gotenberg/unoconverter" "false")
|
||||
download_file "https://raw.githubusercontent.com/gotenberg/unoconverter/${UNOCONVERTER_VERSION}/unoconv" /usr/local/bin/unoconverter
|
||||
chmod +x /usr/local/bin/unoconverter
|
||||
msg_ok "Updated unoconverter"
|
||||
|
||||
msg_info "Starting Service"
|
||||
systemctl start gotenberg
|
||||
msg_ok "Started Service"
|
||||
msg_ok "Updated Successfully!"
|
||||
fi
|
||||
exit
|
||||
}
|
||||
|
||||
start
|
||||
build_container
|
||||
description
|
||||
|
||||
msg_ok "Completed Successfully!\n"
|
||||
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
|
||||
echo -e "${INFO}${YW}Gotenberg is a stateless API and has no web interface.${CL}"
|
||||
echo -e "${INFO}${YW}Check the health endpoint using the following URL:${CL}"
|
||||
echo -e "${GATEWAY}${BGN}http://${IP}:3000/health${CL}"
|
||||
@@ -0,0 +1,58 @@
|
||||
#!/usr/bin/env bash
|
||||
_CS_DEFAULT_URL="https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main"
|
||||
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
|
||||
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: MickLesk (CanbiZ)
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://github.com/Darkrock-Studios/hammer-editor
|
||||
|
||||
APP="Hammer"
|
||||
var_tags="${var_tags:-writing;sync-server}"
|
||||
var_cpu="${var_cpu:-2}"
|
||||
var_ram="${var_ram:-2048}"
|
||||
var_disk="${var_disk:-8}"
|
||||
var_os="${var_os:-debian}"
|
||||
var_version="${var_version:-13}"
|
||||
var_unprivileged="${var_unprivileged:-1}"
|
||||
var_arm64="${var_arm64:-yes}"
|
||||
|
||||
header_info "$APP"
|
||||
variables
|
||||
color
|
||||
catch_errors
|
||||
|
||||
function update_script() {
|
||||
header_info
|
||||
check_container_storage
|
||||
check_container_resources
|
||||
|
||||
if [[ ! -d /opt/hammer ]]; then
|
||||
msg_error "No ${APP} Installation Found!"
|
||||
exit
|
||||
fi
|
||||
|
||||
if check_for_gh_release "hammer" "Darkrock-Studios/hammer-editor"; then
|
||||
msg_info "Stopping Service"
|
||||
systemctl stop hammer
|
||||
msg_ok "Stopped Service"
|
||||
|
||||
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "hammer" "Darkrock-Studios/hammer-editor" "prebuild" "latest" "/opt/hammer" "server.zip"
|
||||
chmod +x /opt/hammer/bin/server
|
||||
|
||||
msg_info "Starting Service"
|
||||
systemctl start hammer
|
||||
msg_ok "Started Service"
|
||||
msg_ok "Updated successfully!"
|
||||
fi
|
||||
exit
|
||||
}
|
||||
|
||||
start
|
||||
build_container
|
||||
description
|
||||
|
||||
msg_ok "Completed Successfully!\n"
|
||||
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
|
||||
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
|
||||
echo -e "${GATEWAY}${BGN}http://${IP}:8080${CL}"
|
||||
@@ -0,0 +1,6 @@
|
||||
______ __ __
|
||||
/ ____/___ / /____ ____ / /_ ___ _________ _
|
||||
/ / __/ __ \/ __/ _ \/ __ \/ __ \/ _ \/ ___/ __ `/
|
||||
/ /_/ / /_/ / /_/ __/ / / / /_/ / __/ / / /_/ /
|
||||
\____/\____/\__/\___/_/ /_/_.___/\___/_/ \__, /
|
||||
/____/
|
||||
@@ -0,0 +1,6 @@
|
||||
__ __
|
||||
/ / / /___ _____ ___ ____ ___ ___ _____
|
||||
/ /_/ / __ `/ __ `__ \/ __ `__ \/ _ \/ ___/
|
||||
/ __ / /_/ / / / / / / / / / / / __/ /
|
||||
/_/ /_/\__,_/_/ /_/ /_/_/ /_/ /_/\___/_/
|
||||
|
||||
+12
-1
@@ -17,6 +17,14 @@ var_version="${var_version:-13}"
|
||||
var_arm64="${var_arm64:-yes}"
|
||||
var_unprivileged="${var_unprivileged:-1}"
|
||||
|
||||
# Optional public setup, read by the install script (all empty = LAN-only install as before).
|
||||
# Without the export they never reach the container.
|
||||
export var_jitsi_domain="${var_jitsi_domain:-}"
|
||||
export var_jitsi_le_email="${var_jitsi_le_email:-}"
|
||||
export var_jitsi_public_ip="${var_jitsi_public_ip:-}"
|
||||
export var_jitsi_admin_user="${var_jitsi_admin_user:-}"
|
||||
export var_jitsi_admin_pass="${var_jitsi_admin_pass:-}"
|
||||
|
||||
header_info "$APP"
|
||||
variables
|
||||
color
|
||||
@@ -50,4 +58,7 @@ description
|
||||
msg_ok "Completed Successfully!\n"
|
||||
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
|
||||
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
|
||||
echo -e "${GATEWAY}${BGN}https://${IP}${CL}"
|
||||
echo -e "${GATEWAY}${BGN}https://${var_jitsi_domain:-$IP}${CL}"
|
||||
if [[ -n "${var_jitsi_domain}" ]]; then
|
||||
echo -e "${INFO}${YW}Forward TCP 80/443 and UDP 10000 to the container. Secure-domain credentials (if enabled) are in ~/jitsi-meet.creds inside the container.${CL}"
|
||||
fi
|
||||
|
||||
+3
-1
@@ -68,7 +68,7 @@ map \$uri \$poznote_coop {
|
||||
|
||||
server {
|
||||
listen 8040;
|
||||
root /var/www/html;
|
||||
root /var/www/html/public;
|
||||
index index.php index.html;
|
||||
|
||||
gzip on;
|
||||
@@ -144,10 +144,12 @@ server {
|
||||
}
|
||||
|
||||
location ~ ^/data/users/[0-9]+/backgrounds/ {
|
||||
root /var/www/html;
|
||||
try_files \$uri =404;
|
||||
}
|
||||
|
||||
location ~ ^/data/css/[A-Za-z0-9._-]+\.css$ {
|
||||
root /var/www/html;
|
||||
try_files \$uri =404;
|
||||
}
|
||||
|
||||
|
||||
@@ -25,7 +25,13 @@ $STD apt install -y \
|
||||
procps \
|
||||
vlc-bin \
|
||||
vlc-plugin-base \
|
||||
streamlink
|
||||
streamlink \
|
||||
autoconf \
|
||||
libtool \
|
||||
libargtable2-dev \
|
||||
libavformat-dev \
|
||||
libsdl2-dev \
|
||||
libswscale-dev
|
||||
msg_ok "Installed Dependencies"
|
||||
|
||||
setup_uv
|
||||
@@ -33,6 +39,15 @@ NODE_VERSION="24" setup_nodejs
|
||||
PG_VERSION="16" setup_postgresql
|
||||
PG_DB_NAME="dispatcharr_db" PG_DB_USER="dispatcharr_usr" setup_postgresql_db
|
||||
fetch_and_deploy_gh_release "dispatcharr" "Dispatcharr/Dispatcharr" "tarball"
|
||||
fetch_and_deploy_gh_release "Comskip" "erikkaashoek/Comskip" "tarball"
|
||||
|
||||
msg_info "Compiling Comskip"
|
||||
cd /opt/Comskip
|
||||
$STD ./autogen.sh
|
||||
$STD ./configure
|
||||
$STD make
|
||||
$STD make install
|
||||
msg_ok "Compiled and Installed Comskip"
|
||||
|
||||
msg_info "Installing Python Dependencies with uv"
|
||||
cd /opt/dispatcharr
|
||||
|
||||
@@ -0,0 +1,96 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: CrazyWolf13
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://github.com/gotenberg/gotenberg
|
||||
|
||||
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
|
||||
color
|
||||
verb_ip6
|
||||
catch_errors
|
||||
setting_up_container
|
||||
network_check
|
||||
update_os
|
||||
|
||||
msg_info "Installing Dependencies"
|
||||
$STD apt install -y \
|
||||
chromium \
|
||||
libreoffice-writer \
|
||||
libreoffice-calc \
|
||||
libreoffice-impress \
|
||||
libreoffice-draw \
|
||||
libreoffice-math \
|
||||
python3-uno \
|
||||
python-is-python3 \
|
||||
pdftk-java \
|
||||
qpdf \
|
||||
libimage-exiftool-perl \
|
||||
fonts-crosextra-carlito \
|
||||
fonts-crosextra-caladea \
|
||||
fonts-liberation \
|
||||
fonts-liberation2 \
|
||||
fonts-dejavu \
|
||||
fonts-noto-cjk \
|
||||
fonts-noto-color-emoji \
|
||||
fonts-noto-core
|
||||
msg_ok "Installed Dependencies"
|
||||
|
||||
fetch_and_deploy_gh_release "pdfcpu" "pdfcpu/pdfcpu" "prebuild" "latest" "/opt/pdfcpu" "pdfcpu_*_Linux_$(arch_resolve "x86_64" "arm64").tar.xz"
|
||||
ln -sf "$(find /opt/pdfcpu -type f -name pdfcpu | head -n1)" /usr/local/bin/pdfcpu
|
||||
|
||||
msg_info "Installing unoconverter"
|
||||
UNOCONVERTER_VERSION=$(get_latest_github_release "gotenberg/unoconverter" "false")
|
||||
download_file "https://raw.githubusercontent.com/gotenberg/unoconverter/${UNOCONVERTER_VERSION}/unoconv" /usr/local/bin/unoconverter
|
||||
chmod +x /usr/local/bin/unoconverter
|
||||
msg_ok "Installed unoconverter"
|
||||
|
||||
fetch_and_deploy_gh_release "gotenberg" "gotenberg/gotenberg" "tarball" "latest" "/opt/gotenberg"
|
||||
|
||||
GO_VERSION="$(awk '$1=="go"{print $2}' /opt/gotenberg/go.mod | cut -d. -f1,2)" setup_go
|
||||
|
||||
msg_info "Building Gotenberg (Patience)"
|
||||
cd /opt/gotenberg
|
||||
export CGO_ENABLED=0
|
||||
$STD go mod download
|
||||
$STD go build -o /usr/local/bin/gotenberg \
|
||||
-ldflags "-s -w -X 'github.com/gotenberg/gotenberg/v8/cmd.Version=$(cat ~/.gotenberg)'" \
|
||||
cmd/gotenberg/main.go
|
||||
msg_ok "Built Gotenberg"
|
||||
|
||||
msg_info "Creating Service"
|
||||
cat <<EOF >/etc/systemd/system/gotenberg.service
|
||||
[Unit]
|
||||
Description=Gotenberg
|
||||
Documentation=https://gotenberg.dev
|
||||
After=network.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=root
|
||||
Environment=LANG=C.UTF-8
|
||||
Environment=LC_ALL=C.UTF-8
|
||||
Environment=PDFTK_BIN_PATH=/usr/bin/pdftk
|
||||
Environment=QPDF_BIN_PATH=/usr/bin/qpdf
|
||||
Environment=EXIFTOOL_BIN_PATH=/usr/bin/exiftool
|
||||
Environment=PDFCPU_BIN_PATH=/usr/local/bin/pdfcpu
|
||||
Environment=CHROMIUM_BIN_PATH=/usr/bin/chromium
|
||||
Environment=CHROMIUM_HYPHEN_DATA_DIR_PATH=/opt/gotenberg/build/chromium-hyphen-data
|
||||
Environment=LIBREOFFICE_BIN_PATH=/usr/lib/libreoffice/program/soffice.bin
|
||||
Environment=UNOCONVERTER_BIN_PATH=/usr/local/bin/unoconverter
|
||||
Environment=OTEL_TRACES_EXPORTER=none
|
||||
Environment=OTEL_METRICS_EXPORTER=none
|
||||
Environment=OTEL_LOGS_EXPORTER=none
|
||||
ExecStart=/usr/local/bin/gotenberg --api-port=3000
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
EOF
|
||||
systemctl enable -q --now gotenberg
|
||||
msg_ok "Created Service"
|
||||
|
||||
motd_ssh
|
||||
customize
|
||||
cleanup_lxc
|
||||
@@ -0,0 +1,100 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: MickLesk (CanbiZ)
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://github.com/Darkrock-Studios/hammer-editor
|
||||
|
||||
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
|
||||
color
|
||||
verb_ip6
|
||||
catch_errors
|
||||
setting_up_container
|
||||
network_check
|
||||
update_os
|
||||
|
||||
msg_info "Installing Dependencies"
|
||||
$STD apt install -y \
|
||||
unzip \
|
||||
fontconfig \
|
||||
libfreetype6
|
||||
msg_ok "Installed Dependencies"
|
||||
|
||||
JAVA_VERSION="21" setup_java
|
||||
|
||||
fetch_and_deploy_gh_release "hammer" "Darkrock-Studios/hammer-editor" "prebuild" "latest" "/opt/hammer" "server.zip"
|
||||
|
||||
msg_info "Configuring Hammer Sync Server"
|
||||
chmod +x /opt/hammer/bin/server
|
||||
mkdir -p /opt/hammer_data
|
||||
cat <<EOF >/opt/hammer_data/config.toml
|
||||
# Hammer Sync Server configuration
|
||||
# Reference: https://github.com/Darkrock-Studios/hammer-editor/blob/develop/docs/HOW-TO-RUN-A-SERVER.md
|
||||
# Loaded automatically from the data directory. Apply changes with:
|
||||
# systemctl restart hammer
|
||||
|
||||
host = "${LOCAL_IP}"
|
||||
port = 8080
|
||||
|
||||
# Hammer clients speak https only and will not connect to plain HTTP. Either put
|
||||
# a TLS reverse proxy in front of this port, or let Hammer terminate TLS itself
|
||||
# with a real certificate (self-signed certs are rejected by the clients).
|
||||
#
|
||||
# Behind a reverse proxy on this host, restrict the plain port to loopback and
|
||||
# set the URL the clients actually use:
|
||||
# bindHosts = ["127.0.0.1", "::1"]
|
||||
# publicUrl = "https://hammer.example.com"
|
||||
#
|
||||
# Hammer terminating TLS itself:
|
||||
# sslPort = 443
|
||||
# [sslCert]
|
||||
# certChainPath = "/etc/letsencrypt/live/hammer.example.com/fullchain.pem"
|
||||
# privateKeyPath = "/etc/letsencrypt/live/hammer.example.com/privkey.pem"
|
||||
# forceHttps = true
|
||||
|
||||
# Per-page social share images. fontconfig and libfreetype6 are already installed.
|
||||
# richLinkPreviews = true
|
||||
|
||||
# communityEnabled = true
|
||||
|
||||
# Storage defaults to an in-process PostgreSQL under /opt/hammer_data/pgdata.
|
||||
# To use an external PostgreSQL instead:
|
||||
# [storage]
|
||||
# type = "remote"
|
||||
# [storage.remote]
|
||||
# host = "db.example.com"
|
||||
# port = 5432
|
||||
# database = "hammer"
|
||||
# user = "hammer"
|
||||
# password = "change-me"
|
||||
# useSsl = true
|
||||
|
||||
# Regenerable render/preview caches, default <data dir>/cache.
|
||||
# [cache]
|
||||
# directory = "/var/tmp/hammer-cache"
|
||||
# maxSizeMb = 200
|
||||
EOF
|
||||
cat <<EOF >/etc/systemd/system/hammer.service
|
||||
[Unit]
|
||||
Description=Hammer Sync Server
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=root
|
||||
WorkingDirectory=/opt/hammer
|
||||
Environment=SERVER_OPTS=-Duser.home=/opt
|
||||
ExecStart=/opt/hammer/bin/server
|
||||
Restart=always
|
||||
RestartSec=5
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
EOF
|
||||
systemctl enable -q --now hammer
|
||||
msg_ok "Configured Hammer Sync Server"
|
||||
|
||||
motd_ssh
|
||||
customize
|
||||
cleanup_lxc
|
||||
@@ -13,6 +13,29 @@ setting_up_container
|
||||
network_check
|
||||
update_os
|
||||
|
||||
# Optional public setup. Leave the hostname empty for a LAN-only install
|
||||
# (container IP, self-signed certificate) - the previous default behaviour.
|
||||
if [[ -z "${var_jitsi_domain:-}" ]]; then
|
||||
read -rp "${TAB3}Public hostname (FQDN, leave empty to use the container IP): " var_jitsi_domain || true
|
||||
fi
|
||||
var_jitsi_domain="${var_jitsi_domain:-$LOCAL_IP}"
|
||||
|
||||
if [[ "$var_jitsi_domain" != "$LOCAL_IP" ]]; then
|
||||
if [[ -z "${var_jitsi_le_email:-}" ]]; then
|
||||
read -rp "${TAB3}E-mail for Let's Encrypt (leave empty for a self-signed certificate): " var_jitsi_le_email || true
|
||||
fi
|
||||
if [[ -z "${var_jitsi_public_ip:-}" ]]; then
|
||||
read -rp "${TAB3}Public IP behind NAT (leave empty to detect via STUN): " var_jitsi_public_ip || true
|
||||
fi
|
||||
if [[ -z "${var_jitsi_admin_user:-}" ]]; then
|
||||
read -rp "${TAB3}Admin user for secure domain (leave empty to let anyone create rooms): " var_jitsi_admin_user || true
|
||||
fi
|
||||
if [[ -n "${var_jitsi_admin_user:-}" && -z "${var_jitsi_admin_pass:-}" ]]; then
|
||||
read -rsp "${TAB3}Admin password (leave empty to generate): " var_jitsi_admin_pass || true
|
||||
echo
|
||||
fi
|
||||
fi
|
||||
|
||||
msg_info "Installing Dependencies"
|
||||
$STD apt install -y nginx
|
||||
msg_ok "Installed Dependencies"
|
||||
@@ -25,11 +48,72 @@ setup_deb822_repo "jitsi" \
|
||||
""
|
||||
|
||||
msg_info "Installing Jitsi Meet"
|
||||
echo "jitsi-videobridge2 jitsi-videobridge/jvb-hostname string ${LOCAL_IP}" | debconf-set-selections
|
||||
echo "jitsi-meet-web-config jitsi-meet/cert-choice select Generate a new self-signed certificate" | debconf-set-selections
|
||||
echo "jitsi-videobridge2 jitsi-videobridge/jvb-hostname string ${var_jitsi_domain}" | debconf-set-selections
|
||||
if [[ -n "${var_jitsi_le_email:-}" ]]; then
|
||||
# acme.sh (used by the packaged Let's Encrypt helper) refuses to install without cron
|
||||
$STD apt install -y cron
|
||||
echo "jitsi-meet-web-config jitsi-meet/cert-choice select Let's Encrypt certificates" | debconf-set-selections
|
||||
echo "jitsi-meet-web-config jitsi-meet/email string ${var_jitsi_le_email}" | debconf-set-selections
|
||||
else
|
||||
echo "jitsi-meet-web-config jitsi-meet/cert-choice select Generate a new self-signed certificate" | debconf-set-selections
|
||||
fi
|
||||
echo "jitsi-meet-web-config jitsi-meet/jaas-choice boolean false" | debconf-set-selections
|
||||
DEBIAN_FRONTEND=noninteractive $STD apt install -y jitsi-meet
|
||||
msg_ok "Installed Jitsi Meet"
|
||||
|
||||
if [[ -n "${var_jitsi_public_ip:-}" ]]; then
|
||||
msg_info "Configuring NAT mapping"
|
||||
# JVB 2.3+ reads this from jvb.conf; sip-communicator.properties is no longer used
|
||||
cat <<EOF >>/etc/jitsi/videobridge/jvb.conf
|
||||
ice4j {
|
||||
harvest {
|
||||
mapping {
|
||||
static-mappings = [
|
||||
{ local-address = "${LOCAL_IP}", public-address = "${var_jitsi_public_ip}" }
|
||||
]
|
||||
}
|
||||
}
|
||||
}
|
||||
EOF
|
||||
systemctl restart jitsi-videobridge2
|
||||
msg_ok "Configured NAT mapping"
|
||||
fi
|
||||
|
||||
if [[ -n "${var_jitsi_admin_user:-}" ]]; then
|
||||
msg_info "Configuring Secure Domain"
|
||||
# Only authenticated users may create rooms; guests join via the anonymous domain.
|
||||
# https://jitsi.github.io/handbook/docs/devops-guide/secure-domain/
|
||||
var_jitsi_admin_pass="${var_jitsi_admin_pass:-$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-16)}"
|
||||
sed -i "0,/authentication = \"jitsi-anonymous\"/s//authentication = \"internal_hashed\"/" \
|
||||
"/etc/prosody/conf.avail/${var_jitsi_domain}.cfg.lua"
|
||||
cat <<EOF >>"/etc/prosody/conf.avail/${var_jitsi_domain}.cfg.lua"
|
||||
|
||||
VirtualHost "guest.${var_jitsi_domain}"
|
||||
authentication = "anonymous"
|
||||
c2s_require_encryption = false
|
||||
EOF
|
||||
cat <<EOF >>/etc/jitsi/jicofo/jicofo.conf
|
||||
jicofo {
|
||||
authentication {
|
||||
enabled = true
|
||||
type = XMPP
|
||||
login-url = "${var_jitsi_domain}"
|
||||
}
|
||||
}
|
||||
EOF
|
||||
sed -i "s|^\s*// anonymousdomain: 'guest.example.com',| anonymousdomain: 'guest.${var_jitsi_domain}',|" \
|
||||
"/etc/jitsi/meet/${var_jitsi_domain}-config.js"
|
||||
$STD prosodyctl register "${var_jitsi_admin_user}" "${var_jitsi_domain}" "${var_jitsi_admin_pass}"
|
||||
cat <<EOF >~/jitsi-meet.creds
|
||||
Jitsi Meet Secure Domain
|
||||
Admin User: ${var_jitsi_admin_user}
|
||||
Admin Password: ${var_jitsi_admin_pass}
|
||||
Add more users: prosodyctl register <name> ${var_jitsi_domain} <password>
|
||||
EOF
|
||||
systemctl restart prosody jicofo jitsi-videobridge2
|
||||
msg_ok "Configured Secure Domain"
|
||||
fi
|
||||
|
||||
motd_ssh
|
||||
customize
|
||||
cleanup_lxc
|
||||
|
||||
@@ -46,7 +46,7 @@ map \$uri \$poznote_coop {
|
||||
|
||||
server {
|
||||
listen 8040;
|
||||
root /var/www/html;
|
||||
root /var/www/html/public;
|
||||
index index.php index.html;
|
||||
|
||||
gzip on;
|
||||
@@ -122,10 +122,12 @@ server {
|
||||
}
|
||||
|
||||
location ~ ^/data/users/[0-9]+/backgrounds/ {
|
||||
root /var/www/html;
|
||||
try_files \$uri =404;
|
||||
}
|
||||
|
||||
location ~ ^/data/css/[A-Za-z0-9._-]+\.css$ {
|
||||
root /var/www/html;
|
||||
try_files \$uri =404;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user